Dark Mode
Website Visits Loading...

Patrick
Nguyen

OT Security Engineer with 5+ years of NERC CIP compliance and ICS security experience at a NextEra Energy subsidiary, specializing in Purdue Model network segmentation, Check Point firewall administration, and secure remote access across IT/OT boundaries. Brings a proven track record of audit-ready compliance governance and hands-on security controls implementation to OT security programs across critical infrastructure environments.

OT Security Engineer
Trans Bay Cable (Energy Infrastructure Subsidiary of NextEra Energy)
Own the firewall and remote-access boundary between corporate IT and the control environment for an HVDC transmission link.
  • Own Check Point R81.20 firewall policy design and administration across PROD and T&D environments — three distributed deployments (dedicated management server with a two-gateway HA cluster) plus one standalone gateway/management deployment — covering 7 gateways and 250+ rules and RBAC policies.
  • Designed and enforced Purdue Model segmentation across Levels 2–5 and the OT DMZ, isolating control networks from corporate and permitting only justified, least-privilege cross-boundary flows in alignment with NERC CIP-005 ESP requirements.
  • Built and own the Interactive Remote Access (IRA) path into OT: users on the corporate VPN reach the DMZ, authenticate to Windows jump hosts (RDS) with a separate DMZ-domain account and RSA MFA, and RBAC-scoped Check Point rules govern onward access into the control network.
  • Maintained NERC CIP-005 firewall rule governance by documenting business justifications and source references for each permitted rule, producing audit-ready evidence for compliance reviews.
  • Managed Cisco Firepower (FMC) / ASA rulesets and Windows host-based firewall policy through Group Policy alongside Check Point to support segmentation within the Purdue architecture.
  • Designed a secure remote-execution pathway between segmented networks using PowerShell Just Enough Administration (JEA), enabling controlled cross-boundary operations without weakening segmentation.
  • Implemented automated, secure configuration backups for Check Point firewalls using SCP with key-based authentication to protect configuration integrity and enable rapid recovery.
  • Configured firewall rules and Active Directory integration to support Dragos deployment, enabling passive OT-specific threat detection and monitoring across segmented control and DMZ networks.
  • Hardened the ICS Active Directory environment by enforcing least-privilege Group Policy and restricting administrative access to critical control systems.
  • Configured PRTG Network Monitor to deliver infrastructure availability alerts to HMI displays, giving operators real-time visibility into IT/OT dependencies such as Active Directory and core network services.
  • Triaged SIEM alerts in Tripwire Log Center by correlating firewall, endpoint, and OT system logs to assess operational impact and validate or dismiss threats within ICS environments.
  • Deployed Trend Micro Apex One across Windows-based endpoints in ICS and DMZ networks, enhancing endpoint visibility and malware protection within segmented OT environments.
  • Performed vulnerability assessments and remediation on IT/OT devices and documented system baselines to support compliance.
  • Led procurement and rollout of a centralized cyber asset inventory system, directed vendor interactions, and authored scopes of work for security projects.
  • Led consolidation of 10+ server racks housing 200+ assets, upgrading power circuits from 20A to 30A to increase capacity and support future infrastructure growth.
IT Security Intern
Trans Bay Cable
  • Assisted in implementation of NERC CIP-007-6 controls, designing firewall rulesets to restrict unnecessary logical ports and services.
  • Conducted port analysis on critical HVDC infrastructure systems, reducing exposed services by approximately 40%.
  • Followed NERC CIP-010-3 configuration change management procedures and created baselines for infrastructure components.
  • Supported enterprise-wide implementation of MFA (DUO) across company endpoints integrated with Active Directory.
Firewalls & Networking
Check Point R81.20 (HA Clusters, RBAC, Identity Awareness), Cisco Firepower / ASA, Network Segmentation, OT DMZ Design, VPN, ACLs, VLANs, TCP/IP Networking, Network Security
OT / ICS Security
Purdue Model Architecture, NERC CIP (CIP-005, CIP-007, CIP-010), Interactive Remote Access (IRA), Dragos, SCADA/ICS Environments, Asset Visibility
Security Operations
SIEM Analysis (Tripwire Log Center), Vulnerability Management, Endpoint Protection (Trend Micro Apex One), PRTG Network Monitoring, Veeam Backup & DR
Identity & Infrastructure
Active Directory, Group Policy (GPO), RBAC, RSA MFA, Duo MFA, Windows Server / RDS Jump Hosts, PowerShell (JEA), Linux, Cisco ISE, TACACS+
Cloud
AWS S3, CloudFront, Route 53, DynamoDB, Lambda, API Gateway, Terraform, GitHub Actions
B.S. Business Administration — Information Technology
Spring 2021
California State University East Bay
Hayward, CA
AWS SAA
Solutions Architect Associate
AWS CCP
Certified Cloud Practitioner